a16z Podcast
Summary & Insights
The current transition in cybersecurity is not a gradual evolution but a “tsunami” that renders decades of established defensive doctrine obsolete. The shift from human-led attacks to AI-driven offense marks a fundamental change in the physics of cyber warfare: attacks have moved from the speed of a human typing at a keyboard to the speed of machine execution, where an AI can probe thousands of network paths in a microsecond—a feat that would require seventy humans to attempt and still likely fail.
Kevin Mandia, the founder of Mandiant, posits that the democratization of high-level expertise through AI is creating a dangerous window of exposure. While nation-state actors have historically operated like “snipers,” utilizing precise, surgical strikes to avoid detection, AI transforms the attack profile into a “drone swarm.” This approach is louder and sloppier but devastatingly more effective, as it can exhaust every possible route into a network simultaneously. For the defender, the traditional “detect and respond” loop is now too slow; if a human is required to validate an alert, the network has already been compromised.
To counter this, Mandia argues that defense must become as autonomous as the offense. His company, Armaden, operates on the premise that you cannot have a viable defense without a world-class offense to train against. By deploying “hyper-attacks”—massive swarms of AI agents that map a network’s metadata twin—Armaden continuously pressures customer environments. This allows them to identify “exploitable risk” rather than just “vulnerabilities,” distinguishing between a theoretical bug and a practical path to remote code execution.
The conversation highlights a critical failure in current AI safety: the gap between AI researchers and domain security experts. Mandia notes that many AI labs underestimate the capabilities of their own models because they lack the “red team” mindset. Armaden solves this by pairing exploit developers with AI engineers, creating a “cage” of deterministic rules and classifiers that allow the AI to be creative enough to find zero-days while preventing it from going rogue.
Looking toward the future of the Security Operations Center (SOC), Mandia predicts a total collapse of current manual processes. The “onion peel” of security—prevent, detect, respond—is compressing. Because AI can proliferate internally at shocking speeds, the only viable strategy is a “force field” of autonomous prevention and immediate, machine-led lockdown. The goal is to move from “hygiene-based” penetration testing to a state of continuous, automated red-teaming.
Finally, Mandia reflects on the business of building in this era. Unlike the self-funded, slow-growth model of Mandiant, the AI age demands extreme speed, aggressive funding, and a “Ferrari engine” of a go-to-market strategy. In a world where the technology changes every two weeks, the only lasting differentiator is not the specific tool—which can be replicated in six months—but the ability to solve the hardest problems for the most demanding enterprise customers and maintain a fanatical level of customer satisfaction.
Major Discussion Themes
The Shift from Sniper to Swarm
The dialogue explores the transition in attack methodology. Traditional high-tier threats (nation-states) were characterized by stealth and precision (the “sniper round”). AI introduces “swarm” dynamics, where volume and speed overwhelm defenses. This democratization means less technical attackers can now achieve results previously reserved for elite state actors, making attribution significantly more difficult.
Exploitable Risk vs. Vulnerability Noise
A recurring point of contention is the difference between traditional pen-testing and AI-driven offense. Mandia argues that most security tools produce “noise” by listing thousands of vulnerabilities. Armaden focuses on exploitability—actually executing the kill chain to prove that data can be exfiltrated. This shifts the CISO’s focus from a long list of patches to a short list of critical, proven entry points.
The Necessity of Autonomous Defense
The speakers agree that the “human-in-the-loop” is now a liability. In the time it takes a human analyst to acknowledge an alert, an AI agent can have already moved laterally across the entire network. The only solution is “autonomous defense” that can apply “tourniquets” or compensating controls in milliseconds, effectively automating the “detect and respond” phase into a “prevent” phase.
The Convergence of AI Safety and Domain Expertise
The discussion delves into why AI models often “surprise” their creators. Mandia asserts that AI researchers often lack the investigative experience to anticipate how a model will be weaponized. He advocates for a hybrid team structure where red-teamers define the “evals” (evaluations) for the AI, ensuring the model is tested against real-world kill chains rather than theoretical safety guardrails.
Enterprise Scaling in the AI Era
Mandia contrasts the “grit and moxie” of early startup culture with the need for “industrialized process” today. Because the market is now crowded and the technology moves at a breakneck pace, he emphasizes that operational discipline, scalable leadership, and a rapid feedback loop between customers and engineers are the only ways to avoid “chaos” during hyper-growth.
Surprising Insights
- The “Zero-Day” Threshold: AI agents have officially crossed the threshold from assisting humans to independently finding zero-days in production environments.
- Open vs. Closed Models: In the cyber domain, the capability gap between open-weight models and closed frontier models is surprisingly small; both reached similar endpoints in finding exploitable risks, differing primarily in cost and speed.
- The 8/20 Kill Chain Rule: When tested against 20 real-world human kill chains, the most advanced models could only complete about 8, suggesting that while AI is fast, high-level strategic “creativity” still has a ceiling.
- The Failure of Deterministic Safety: Overly strict guardrails can neuter an AI’s ability to find complex vulnerabilities; the “art” is using classifiers to monitor outbound prompts rather than blocking them preemptively.
- The Speed of Internal Proliferation: Once an AI agent gains internal access, its ability to move laterally is described as “shocking” compared to the linear, step-by-step process of a human hacker.
- The “Metadata Twin” Strategy: Rather than attacking a network constantly (which is cost-prohibitive), the most efficient AI defense involves creating a metadata map and “polling” for changes to attack only what has shifted.
- The “Digital Cocktail Party”: Every major enterprise is currently in a state of “war-room” urgency, realizing simultaneously that their existing defenses are insufficient for AI-led attacks.
Practical Takeaways
- Audit for Exploitability, Not Vulnerability: Stop prioritizing patches based on CVSS scores alone; prioritize based on whether the vulnerability provides a proven path to remote code execution.
- Implement a “Heartbeat” Monitoring System: Move away from annual or quarterly pen-tests toward a continuous polling system that triggers a re-assessment whenever the network configuration or app version changes.
- Build a “Force Field” Mentality: Shift the security budget from “detection” (finding the bad guy after they are in) to “autonomous prevention” (stopping the entry in milliseconds).
- Hybridize Your AI Teams: If building AI tools, ensure “red teamers” (exploit developers) are the ones designing the evaluation frameworks, not just the AI researchers.
- Adopt “Field Dressing” Controls: In the face of a new zero-day, deploy “compensating controls” (rudimentary blocks) immediately to stop the bleeding, rather than waiting for a perfect vendor patch.
- Prioritize the “Hardest Problem” Customers: To build a brand in a crowded AI market, focus exclusively on the most complex enterprise environments (banks, airlines); success there creates a “seal of approval” that scales.
- Minimize Distributed Friction: For high-velocity engineering, favor co-located teams to reduce the communication latency inherent in distributed AI development.
Sự chuyển đổi hiện nay trong lĩnh vực an ninh mạng không phải là một cuộc tiến hóa dần dần mà là một “cơn sóng thần” khiến những học thuyết phòng thủ đã được thiết lập trong nhiều thập kỷ trở nên lỗi thời. Sự chuyển dịch từ các cuộc tấn công do con người dẫn dắt sang tấn công do AI điều khiển đánh dấu một thay đổi cơ bản trong “vật lý” của chiến tranh mạng: tốc độ tấn công đã chuyển từ tốc độ gõ phím của con người sang tốc độ thực thi của máy móc, nơi một AI có thể rà soát hàng nghìn đường dẫn mạng trong một micro giây—một kỳ tích mà 70 con người cùng thực hiện vẫn có khả năng thất bại.
Kevin Mandia, người sáng lập Mandiant, cho rằng việc AI “bình dân hóa” các chuyên môn cấp cao đang tạo ra một khoảng hở nguy hiểm. Trong khi các tác nhân cấp quốc gia trước đây hoạt động như những “tay súng bắn tỉa”, sử dụng các cuộc tấn công chính xác, mang tính phẫu thuật để tránh bị phát hiện, thì AI biến hồ sơ tấn công thành một “đàn drone”. Cách tiếp cận này ồn ào hơn và cẩu thả hơn nhưng lại hiệu quả một cách tàn khốc, vì nó có thể vắt kiệt mọi tuyến đường khả dĩ để xâm nhập vào một mạng lưới cùng một lúc. Đối với bên phòng thủ, vòng lặp “phát hiện và phản ứng” truyền thống giờ đây quá chậm; nếu cần một con người để xác nhận cảnh báo, thì mạng lưới đó thực tế đã bị xâm nhập.
Để đối phó với điều này, Mandia lập luận rằng phòng thủ phải trở nên tự động hóa tương đương với tấn công. Công ty của ông, Armaden, hoạt động dựa trên tiền đề rằng bạn không thể có một hệ thống phòng thủ khả thi nếu không có một hệ thống tấn công đẳng cấp thế giới để huấn luyện. Bằng cách triển khai các cuộc “siêu tấn công” (hyper-attacks)—những đàn tác nhân AI khổng lồ mô phỏng bản sao siêu dữ liệu của mạng lưới—Armaden liên tục tạo áp lực lên môi trường của khách hàng. Điều này cho phép họ xác định “rủi ro có thể khai thác” thay vì chỉ là “lỗ hổng”, phân biệt rõ ràng giữa một lỗi lý thuyết và một con đường thực tế dẫn đến việc thực thi mã từ xa (remote code execution).
Cuộc đối thoại làm nổi bật một thất bại nghiêm trọng trong an toàn AI hiện nay: khoảng cách giữa các nhà nghiên cứu AI và các chuyên gia bảo mật chuyên sâu. Mandia lưu ý rằng nhiều phòng thí nghiệm AI đánh giá thấp khả năng của chính các mô hình của họ vì họ thiếu tư duy của một “đội đỏ” (red team). Armaden giải quyết vấn đề này bằng cách kết hợp các nhà phát triển mã khai thác (exploit developers) với các kỹ sư AI, tạo ra một “chiếc lồng” gồm các quy tắc và bộ phân loại xác định, cho phép AI đủ sáng tạo để tìm ra các lỗ hổng zero-day trong khi ngăn không cho nó hoạt động mất kiểm soát.
Nhìn về tương lai của Trung tâm Điều hành An ninh (SOC), Mandia dự báo về sự sụp đổ hoàn toàn của các quy trình thủ công hiện nay. Mô hình “bóc vỏ hành” của bảo mật—ngăn chặn, phát hiện, phản ứng—đang bị nén lại. Vì AI có thể lan rộng nội bộ với tốc độ gây sốc, chiến lược khả thi duy nhất là một “trường lực” ngăn chặn tự động và phong tỏa tức thì do máy móc dẫn dắt. Mục tiêu là chuyển từ kiểm thử xâm nhập “dựa trên vệ sinh” (hygiene-based) sang trạng thái tấn công giả lập (red-teaming) tự động và liên tục.
Cuối cùng, Mandia suy ngẫm về việc kinh doanh trong kỷ nguyên này. Khác với mô hình tự cấp vốn, tăng trưởng chậm của Mandiant, thời đại AI đòi hỏi tốc độ cực nhanh, nguồn vốn quyết liệt và một chiến lược thâm nhập thị trường với “động cơ Ferrari”. Trong một thế giới mà công nghệ thay đổi sau mỗi hai tuần, điểm khác biệt bền vững duy nhất không phải là một công cụ cụ thể—thứ có thể bị sao chép trong sáu tháng—mà là khả năng giải quyết những vấn đề khó nhất cho những khách hàng doanh nghiệp khắt khe nhất và duy trì mức độ hài lòng tuyệt đối của khách hàng.
Các chủ đề thảo luận chính
Từ Súng bắn tỉa đến Đàn ong
Cuộc đối thoại khám phá sự chuyển đổi trong phương pháp tấn công. Các mối đe dọa cấp cao truyền thống (các quốc gia) đặc trưng bởi sự lén lút và chính xác (“viên đạn bắn tỉa”). AI đưa vào động lực của “đàn ong”, nơi khối lượng và tốc độ áp đảo các hệ thống phòng thủ. Sự bình dân hóa này có nghĩa là những kẻ tấn công ít kỹ thuật hơn giờ đây có thể đạt được kết quả mà trước đây chỉ dành cho các tác nhân tinh nhuệ của nhà nước, khiến việc truy vết nguồn gốc trở nên khó khăn hơn đáng kể.
Rủi ro có thể khai thác và Nhiễu lỗ hổng
Một điểm tranh luận thường xuyên là sự khác biệt giữa kiểm thử xâm nhập (pen-testing) truyền thống và tấn công do AI dẫn dắt. Mandia lập luận rằng hầu hết các công cụ bảo mật tạo ra “nhiễu” bằng cách liệt kê hàng nghìn lỗ hổng. Armaden tập trung vào khả năng khai thác—thực sự thực thi chuỗi tấn công (kill chain) để chứng minh rằng dữ liệu có thể bị đánh cắp. Điều này chuyển trọng tâm của Giám đốc An ninh thông tin (CISO) từ một danh sách dài các bản vá sang một danh sách ngắn các điểm xâm nhập trọng yếu đã được chứng minh.
Sự cần thiết của Phòng thủ Tự động
Các diễn giả đồng ý rằng việc “có con người trong quy trình” (human-in-the-loop) hiện nay là một điểm yếu. Trong thời gian một chuyên gia phân tích con người xác nhận cảnh báo, một tác nhân AI có thể đã di chuyển ngang (lateral movement) qua toàn bộ mạng lưới. Giải pháp duy nhất là “phòng thủ tự động” có thể áp dụng các “biện pháp cầm máu” hoặc kiểm soát bù đắp trong vài mili giây, biến giai đoạn “phát hiện và phản ứng” thành giai đoạn “ngăn chặn”.
Sự hội tụ giữa An toàn AI và Chuyên môn miền
Cuộc thảo luận đi sâu vào lý do tại sao các mô hình AI thường gây “bất ngờ” cho chính những người tạo ra chúng. Mandia khẳng định rằng các nhà nghiên cứu AI thường thiếu kinh nghiệm điều tra để dự đoán cách một mô hình sẽ bị vũ khí hóa. Ông ủng hộ cấu trúc nhóm hỗn hợp, nơi các thành viên red-team định nghĩa các “bài đánh giá” (evals) cho AI, đảm bảo mô hình được thử nghiệm với các chuỗi tấn công thực tế thay vì các rào chắn an toàn lý thuyết.
Mở rộng quy mô doanh nghiệp trong kỷ nguyên AI
Mandia đối lập sự “kiên cường và bản lĩnh” của văn hóa khởi nghiệp thời kỳ đầu với nhu cầu về “quy trình công nghiệp hóa” ngày nay. Vì thị trường hiện nay đang chật chội và công nghệ tiến triển với tốc độ chóng mặt, ông nhấn mạnh rằng kỷ luật vận hành, năng lực lãnh đạo có khả năng mở rộng và vòng lặp phản hồi nhanh chóng giữa khách hàng và kỹ sư là những cách duy nhất để tránh “sự hỗn loạn” trong giai đoạn tăng trưởng nóng.
Những hiểu biết bất ngờ
- Ngưỡng “Zero-Day”: Các tác nhân AI đã chính thức vượt qua ngưỡng từ việc hỗ trợ con người sang tự tìm ra các lỗ hổng zero-day trong môi trường vận hành thực tế.
- Mở đối lập với…
Đây là bản dịch chuyên nghiệp, giữ nguyên các thẻ HTML để bạn dễ dàng sử dụng:
- Các Mô hình Đóng: Trong lĩnh vực an ninh mạng, khoảng cách về năng lực giữa các mô hình mở (open-weight) và các mô hình tiên phong đóng (closed frontier models) nhỏ đến mức đáng ngạc nhiên; cả hai đều đạt được kết quả tương đương trong việc tìm ra các rủi ro có thể khai thác, điểm khác biệt chủ yếu nằm ở chi phí và tốc độ.
- Quy tắc Chuỗi tấn công 8/20: Khi thử nghiệm với 20 chuỗi tấn công (kill chains) thực tế của con người, các mô hình tiên tiến nhất chỉ có thể hoàn thành khoảng 8 chuỗi. Điều này cho thấy mặc dù AI có tốc độ nhanh, nhưng “khả năng sáng tạo” chiến lược cấp cao vẫn có một ngưỡng giới hạn.
- Sự thất bại của An toàn Định sẵn (Deterministic Safety): Các rào chắn (guardrails) quá nghiêm ngặt có thể làm tê liệt khả năng tìm kiếm các lỗ hổng phức tạp của AI; “nghệ thuật” ở đây là sử dụng các bộ phân loại (classifiers) để giám sát các câu lệnh đầu ra thay vì ngăn chặn chúng một cách tiên quyết.
- Tốc độ Lan truyền Nội bộ: Một khi tác nhân AI giành được quyền truy cập nội bộ, khả năng di chuyển ngang (lateral move) của nó được mô tả là “gây sốc” so với quy trình tuyến tính, từng bước một của một hacker là con người.
- Chiến lược “Song sinh Siêu dữ liệu” (Metadata Twin): Thay vì tấn công mạng liên tục (điều vốn gây tốn kém chi phí), phương pháp phòng thủ AI hiệu quả nhất là tạo ra một bản đồ siêu dữ liệu và “thăm dò” (polling) các thay đổi để chỉ tấn công vào những phần vừa biến động.
- “Bữa tiệc Cocktail Kỹ thuật số”: Mọi doanh nghiệp lớn hiện nay đều đang trong tình trạng khẩn cấp như trong “phòng tác chiến”, khi họ đồng loạt nhận ra rằng hệ thống phòng thủ hiện tại không đủ khả năng chống lại các cuộc tấn công do AI dẫn dắt.
Bài học Thực tiễn
- Kiểm tra Khả năng Khai thác, không chỉ Lỗ hổng: Ngừng ưu tiên các bản vá chỉ dựa trên điểm CVSS; hãy ưu tiên dựa trên việc liệu lỗ hổng đó có cung cấp một lộ trình thực tế để thực thi mã từ xa (remote code execution) hay không.
- Triển khai Hệ thống Giám sát “Nhịp tim” (Heartbeat): Chuyển từ kiểm tra xâm nhập (pen-test) hàng năm hoặc hàng quý sang hệ thống thăm dò liên tục, tự động kích hoạt đánh giá lại bất cứ khi nào cấu hình mạng hoặc phiên bản ứng dụng thay đổi.
- Xây dựng Tư duy “Trường Lực”: Chuyển ngân sách bảo mật từ “phát hiện” (tìm kẻ xấu sau khi chúng đã xâm nhập) sang “ngăn chặn tự động” (chặn đứng việc xâm nhập trong vài mili giây).
- Lai hóa Đội ngũ AI: Nếu xây dựng các công cụ AI, hãy đảm bảo rằng những “red teamers” (nhà phát triển khai thác lỗi) là những người thiết kế khung đánh giá, chứ không chỉ là các nhà nghiên cứu AI.
- Áp dụng Kiểm soát “Sơ cứu” (Field Dressing): Khi đối mặt với một lỗ hổng zero-day mới, hãy triển khai các “kiểm soát bù đắp” (các lệnh chặn thô sơ) ngay lập tức để “cầm máu”, thay vì chờ đợi một bản vá hoàn hảo từ nhà cung cấp.
- Ưu tiên những Khách hàng có “Bài toán Khó nhất”: Để xây dựng thương hiệu trong một thị trường AI đông đúc, hãy tập trung duy nhất vào các môi trường doanh nghiệp phức tạp nhất (ngân hàng, hàng không); thành công tại đó sẽ tạo ra một “con dấu bảo chứng” giúp mở rộng quy mô dễ dàng hơn.
- Giảm thiểu Ma sát Phân tán: Để đạt tốc độ kỹ thuật cao, hãy ưu tiên các đội ngũ làm việc tập trung (co-located) nhằm giảm độ trễ trong giao tiếp vốn thường thấy trong phát triển AI phân tán.
目前的網路安全轉型並非漸進的演變,而是一場將數十年既有防禦準則化為烏有地「海嘯」。從人類主導的攻擊轉向 AI 驅動的攻勢,標誌著網路戰爭物理特性的根本改變:攻擊速度已從人類在鍵盤上的輸入速度,轉變為機器執行的速度。AI 能在微秒內探測數千條網路路徑——這項壯舉即使由七十名人類嘗試也極可能失敗。
Mandiant 的創始人 Kevin Mandia 指出,AI 讓高階專業知識變得平民化,正造成一個危險的曝險窗口。過去,國家級攻擊者運作起來像「狙擊手」,利用精準的外科手術式打擊以避免被發現;而 AI 將攻擊模式轉變為「無人機蜂群」。這種方式雖然較為嘈雜且粗糙,但效果卻極為驚人,因為它能同時嘗試進入網路的所有可能路徑。對於防禦者而言,傳統的「偵測與響應」循環如今過於緩慢;如果還需要人類來驗證警報,網路恐怕早已被攻破。
為了應對這一挑戰,Mandia 主張防禦必須變得與攻勢一樣自動化。他的公司 Armaden 的運作前提是:如果沒有世界頂尖的攻勢來進行對抗訓練,就無法建立有效的防禦。透過部署「超強攻擊」(hyper-attacks)——即大量 AI 代理集群來對應網路的元數據雙生(metadata twin)——Armaden 持續對客戶環境施壓。這使他們能夠識別出「可利用的風險」(exploitable risk),而非僅僅是「漏洞」(vulnerabilities),從而區分理論上的 Bug 與實際可實現的遠端程式碼執行路徑。
這次對話凸顯了目前 AI 安全的一個關鍵失敗:AI 研究人員與領域安全專家之間的鴻溝。Mandia 注意到,許多 AI 實驗室低估了自家模型的能力,因為他們缺乏「紅隊」(red team)思維。Armaden 透過將漏洞開發人員與 AI 工程師配對來解決此問題,建立一個由確定性規則和分類器組成的「籠子」,讓 AI 既能保持足夠的創造力來尋找零日漏洞(zero-days),同時防止其失控。
展望安全維運中心(SOC)的未來,Mandia 預測目前的手動流程將全面崩潰。安全防禦的「剝洋蔥」層級——預防、偵測、響應——正在被壓縮。由於 AI 能以驚人的速度在內部擴散,唯一可行的策略是建立一個由自動化預防和即時機器鎖定構成的「力場」。其目標是從「基於衛生習慣」(hygiene-based)的滲透測試,轉向持續且自動化的紅隊演練狀態。
最後,Mandia 反思了在這個時代創業的商業邏輯。不同於 Mandiant 早期自籌資金、緩慢成長的模式,AI 時代要求極致的速度、激進的融資以及如「法拉利引擎」般強大的市場進入策略。在技術每兩週就變一次的世界裡,唯一持久的競爭優勢不是特定的工具(因為工具在半年內就能被複製),而是為最苛刻的企業客戶解決最困難問題的能力,並維持一種近乎狂熱的客戶滿意度。
主要討論主題
從狙擊手到蜂群的轉變
對話探討了攻擊方法的轉型。傳統的高階威脅(國家級攻擊者)以隱蔽和精準為特徵(如「狙擊彈」)。AI 則引入了「蜂群」動態,利用數量和速度壓垮防禦。這種平民化意味著技術含量較低的攻擊者現在也能達成以往僅限於頂尖國家級特工才能實現的結果,使得溯源(attribution)變得更加困難。
可利用風險 vs. 漏洞噪音
一個反覆出現的爭論點是傳統滲透測試與 AI 驅動攻勢之間的區別。Mandia 主張大多數安全工具通過列出數千個漏洞來製造「噪音」。Armaden 則專注於「可利用性」——實際執行攻擊鏈(kill chain)以證明數據可以被外洩。這將資訊安全長(CISO)的關注點從冗長的補丁清單轉移到少數關鍵且經證實的進入點上。
自動化防禦的必要性
講者一致認為,「人機協作」(human-in-the-loop)現在已成為一種負擔。在人類分析師確認警報所需的時間內,AI 代理可能已經在整個網絡中完成了橫向移動。唯一的解決方案是「自動化防禦」,能在毫秒內施加「止血帶」或補償性控制,有效地將「偵測與響應」階段自動化為「預防」階段。
AI 安全與領域專業知識的融合
討論深入探討了為什麼 AI 模型經常讓其創造者感到「驚訝」。Mandia 斷言,AI 研究人員通常缺乏調查經驗,無法預見模型將如何被武器化。他倡導一種混合團隊結構,由紅隊人員為 AI 定義「評估指標」(evals),確保模型是根據現實世界的攻擊鏈而非理論上的安全護欄來進行測試。
AI 時代的企業規模化
Mandia 將早期創業文化中的「韌性與膽識」與今日對「工業化流程」的需求進行對比。由於市場現已擁擠且技術演進速度極快,他強調運作紀律、可擴展的領導力以及客戶與工程師之間的快速反饋循環,是避免在超速成長期間陷入「混亂」的唯一途徑。
驚人洞見
- 「零日漏洞」門檻: AI 代理已正式跨越門檻,從協助人類轉變為能獨立在生產環境中發現零日漏洞。
- 開源 vs.
實務要點
- 審核「可利用性」而非僅是「漏洞」:停止僅根據 CVSS 分數來決定補丁優先順序;應優先考慮該漏洞是否提供了經證實的遠端程式碼執行(RCE)路徑。
- 實施「心跳」監控系統:從年度或季度性的滲透測試,轉向連續輪詢系統,每當網路配置或應用程式版本發生變化時,立即觸發重新評估。
- 建立「力場」思維:將安全預算從「偵測」(在入侵者進入後將其找出)轉向「自主預防」(在毫秒內阻止進入)。
- AI 團隊混合化:在構建 AI 工具時,確保由「紅隊人員」(漏洞利用開發者)而非僅由 AI 研究人員來設計評估框架。
- 採取「野戰包紮」式控制:面對新的零日漏洞(Zero-day)時,立即部署「補償性控制」(初步封鎖)以止血,而非等待供應商提供完美的補丁。
- 優先服務「最難搞」的客戶:在擁擠的 AI 市場中建立品牌,應專注於最複雜的企業環境(如銀行、航空公司);在那裡的成功將創造一個可擴展的「認證標誌」。
- 最小化分佈式摩擦:為了實現高速度的工程開發,優先選擇協作地點相近的團隊,以減少分佈式 AI 開發中固有的溝通延遲。
La transition actuelle en matière de cybersécurité n’est pas une évolution graduelle, mais un « tsunami » qui rend obsolètes des décennies de doctrines défensives établies. Le passage d’attaques dirigées par l’homme à une offensive pilotée par l’IA marque un changement fondamental dans la « physique » de la guerre cybernétique : les attaques sont passées de la vitesse d’un humain tapant sur un clavier à celle de l’exécution machine, où une IA peut sonder des milliers de chemins réseau en une microseconde — une prouesse qui nécessiterait l’intervention de soixante-dix humains pour être tentée, tout en ayant de fortes chances d’échouer.
Kevin Mandia, fondateur de Mandiant, avance que la démocratisation de l’expertise de haut niveau via l’IA crée une fenêtre d’exposition dangereuse. Alors que les acteurs étatiques opéraient historiquement comme des « snipers », utilisant des frappes chirurgicales et précises pour éviter la détection, l’IA transforme le profil d’attaque en un « essaim de drones ». Cette approche est plus bruyante et moins soignée, mais dévastatrice par son efficacité, car elle peut épuiser simultanément toutes les routes d’accès possibles à un réseau. Pour le défenseur, la boucle traditionnelle « détecter et répondre » est désormais trop lente ; si l’intervention d’un humain est requise pour valider une alerte, le réseau est déjà compromis.
Pour contrer cela, Mandia soutient que la défense doit devenir aussi autonome que l’offensive. Son entreprise, Armaden, repose sur le principe qu’une défense viable est impossible sans une offensive de classe mondiale pour s’entraîner. En déployant des « hyper-attaques » — des essaims massifs d’agents IA qui cartographient le jumeau numérique des métadonnées d’un réseau — Armaden exerce une pression continue sur les environnements de ses clients. Cela leur permet d’identifier le « risque exploitable » plutôt que de simples « vulnérabilités », distinguant ainsi un bug théorique d’un chemin concret menant à l’exécution de code à distance.
La conversation met en lumière un échec critique de la sécurité actuelle de l’IA : le fossé entre les chercheurs en IA et les experts en sécurité du domaine. Mandia note que de nombreux laboratoires d’IA sous-estiment les capacités de leurs propres modèles car ils manquent de l’état d’esprit « red team ». Armaden résout ce problème en associant des développeurs d’exploits à des ingénieurs en IA, créant ainsi une « cage » de règles déterministes et de classificateurs qui permettent à l’IA d’être assez créative pour trouver des failles zero-day tout en l’empêchant de devenir incontrôlable.
S’agissant de l’avenir du centre d’opérations de sécurité (SOC), Mandia prévoit un effondrement total des processus manuels actuels. La structure en « couches d’oignon » de la sécurité — prévenir, détecter, répondre — est en train de se compresser. Parce que l’IA peut proliférer en interne à des vitesses stupéfiantes, la seule stratégie viable est un « champ de force » de prévention autonome et un verrouillage immédiat piloté par la machine. L’objectif est de passer de tests d’intrusion basés sur l’hygiène à un état de red-teaming continu et automatisé.
Enfin, Mandia réfléchit à la manière de bâtir une entreprise à cette époque. Contrairement au modèle de Mandiant, autofinancé et à croissance lente, l’ère de l’IA exige une vitesse extrême, un financement agressif et une stratégie de mise sur le marché comparable à un « moteur de Ferrari ». Dans un monde où la technologie change toutes les deux semaines, le seul différenciateur durable n’est pas l’outil spécifique — qui peut être répliqué en six mois — mais la capacité à résoudre les problèmes les plus complexes pour les clients d’entreprise les plus exigeants, tout en maintenant un niveau fanatique de satisfaction client.
Thèmes principaux de la discussion
Du sniper à l’essaim
Le dialogue explore la transition des méthodologies d’attaque. Les menaces de haut niveau traditionnelles (États-nations) se caractérisaient par la furtivité et la précision (la « balle de sniper »). L’IA introduit une dynamique d’« essaim », où le volume et la vitesse submergent les défenses. Cette démocratisation signifie que des attaquants moins techniques peuvent désormais obtenir des résultats auparavant réservés aux acteurs étatiques d’élite, rendant l’attribution nettement plus difficile.
Risque exploitable vs bruit des vulnérabilités
Un point de divergence récurrent est la différence entre les tests d’intrusion traditionnels et l’offensive pilotée par l’IA. Mandia soutient que la plupart des outils de sécurité produisent du « bruit » en listant des milliers de vulnérabilités. Armaden se concentre sur l’exploitabilité — l’exécution réelle de la chaîne d’attaque (kill chain) pour prouver que des données peuvent être exfiltrées. Cela déplace l’attention du RSSI d’une longue liste de correctifs vers une liste courte de points d’entrée critiques et prouvés.
La nécessité d’une défense autonome
Les intervenants s’accordent sur le fait que la présence humaine dans la boucle (« human-in-the-loop ») est désormais un handicap. Le temps qu’un analyste humain accuse réception d’une alerte, un agent IA a déjà pu se déplacer latéralement sur l’ensemble du réseau. La seule solution est une « défense autonome » capable d’appliquer des « garrots » ou des contrôles compensatoires en quelques millisecondes, transformant ainsi la phase « détecter et répondre » en une phase de « prévention » automatisée.
Convergence entre sécurité de l’IA et expertise métier
La discussion approfondit les raisons pour lesquelles les modèles d’IA « surprennent » souvent leurs créateurs. Mandia affirme que les chercheurs en IA manquent souvent de l’expérience d’enquête nécessaire pour anticiper la manière dont un modèle sera militarisé. Il préconise une structure d’équipe hybride où les red-teamers définissent les « evals » (évaluations) de l’IA, garantissant que le modèle est testé face à des chaînes d’attaque réelles plutôt que face à des garde-fous de sécurité théoriques.
Le passage à l’échelle des entreprises à l’ère de l’IA
Mandia oppose le « cran et l’audace » de la culture startup des débuts au besoin actuel de « processus industrialisés ». Le marché étant désormais saturé et la technologie évoluant à un rythme effréné, il souligne que la discipline opérationnelle, un leadership évolutif et une boucle de rétroaction rapide entre clients et ingénieurs sont les seuls moyens d’éviter le « chaos » lors d’une hyper-croissance.
Perspectives surprenantes
- Le seuil du « Zero-Day » : Les agents IA ont officiellement franchi le seuil où ils ne se contentent plus d’assister les humains, mais trouvent indépendamment des failles zero-day dans des environnements de production.
- Open vs…
Here is the professional translation into French, maintaining the HTML structure:
- Modèles fermés : Dans le domaine cyber, l’écart de capacité entre les modèles à poids ouverts (open-weight) et les modèles de pointe fermés est étonnamment réduit ; les deux sont parvenus à des résultats similaires dans l’identification de risques exploitables, différant principalement par le coût et la vitesse.
- La règle de la « Kill Chain » 8/20 : Testés face à 20 chaînes d’attaque (kill chains) humaines réelles, les modèles les plus avancés n’ont pu en compléter qu’environ 8, suggérant que si l’IA est rapide, la « créativité » stratégique de haut niveau possède toujours un plafond.
- L’échec de la sécurité déterministe : Des garde-fous trop stricts peuvent neutraliser la capacité d’une IA à trouver des vulnérabilités complexes ; « l’art » consiste à utiliser des classificateurs pour surveiller les requêtes sortantes plutôt que de les bloquer préemptivement.
- La vitesse de prolifération interne : Une fois qu’un agent IA obtient un accès interne, sa capacité de déplacement latéral est décrite comme « choquante » comparée au processus linéaire et étape par étape d’un hacker humain.
- La stratégie du « Jumeau de Métadonnées » : Plutôt que d’attaquer un réseau en continu (ce qui est prohibitif en termes de coût), la défense IA la plus efficace consiste à créer une carte des métadonnées et à effectuer un « sondage » des changements pour n’attaquer que ce qui a évolué.
- La « Cocktail Party numérique » : Chaque grande entreprise se trouve actuellement dans un état d’urgence type « war-room », réalisant simultanément que leurs défenses actuelles sont insuffisantes face aux attaques menées par l’IA.
enseignements pratiques
- Auditer l’exploitabilité, pas la vulnérabilité : Cessez de prioriser les correctifs en vous basant uniquement sur les scores CVSS ; priorisez en fonction de la question de savoir si la vulnérabilité offre un chemin prouvé vers l’exécution de code à distance.
- Implémenter un système de surveillance « Heartbeat » : Passez des tests d’intrusion annuels ou trimestriels à un système de sondage continu qui déclenche une réévaluation dès que la configuration du réseau ou la version d’une application change.
- Adopter une mentalité de « Champ de Force » : Réorientez le budget de sécurité de la « détection » (trouver l’intrus après son entrée) vers la « prévention autonome » (bloquer l’entrée en quelques millisecondes).
- Hybrider vos équipes IA : Si vous développez des outils d’IA, assurez-vous que les « red teamers » (développeurs d’exploits) soient ceux qui conçoivent les cadres d’évaluation, et pas seulement les chercheurs en IA.
- Adopter des contrôles de « Premiers Secours » : Face à une nouvelle faille zero-day, déployez immédiatement des « contrôles compensatoires » (blocages rudimentaires) pour stopper l’hémorragie, plutôt que d’attendre le correctif parfait du fournisseur.
- Prioriser les clients ayant les « Problèmes les plus Difficiles » : Pour bâtir une marque dans un marché de l’IA saturé, concentrez-vous exclusivement sur les environnements d’entreprise les plus complexes (banques, compagnies aériennes) ; le succès dans ces domaines crée un « label de qualité » évolutif.
- Minimiser la friction distribuée : Pour une ingénierie à haute vélocité, privilégiez les équipes colocalisées afin de réduire la latence de communication inhérente au développement d’IA distribué.
Der aktuelle Wandel in der Cybersicherheit ist keine graduelle Evolution, sondern ein „Tsunami“, der jahrzehntelang etablierte Verteidigungsdoktrinen hinfällig macht. Der Übergang von menschlich gesteuerten Angriffen zu KI-gesteuerten Offensiven markiert eine grundlegende Änderung in der Physik der Cyberkriegsführung: Angriffe haben sich von der Geschwindigkeit eines Menschen, der auf einer Tastatur tippt, zur Geschwindigkeit einer Maschinenexécution bewegt, bei der eine KI in einer Mikrosekunde Tausende von Netzwerkpfaden sondieren kann – eine Leistung, für die siebzig Menschen nötig wären und die dennoch wahrscheinlich scheitern würde.
Kevin Mandia, der Gründer von Mandiant, vertritt die Ansicht, dass die Demokratisierung von hochspezialisiertem Expertenwissen durch KI ein gefährliches Zeitfenster der Exponiertheit schafft. Während staatliche Akteure historisch wie „Scharfschützen“ agierten und präzise, chirurgische Schläge nutzten, um Entdeckung zu vermeiden, transformiert KI das Angriffsprofil in einen „Drohnenschwarm“. Dieser Ansatz ist lauter und unpräziser, aber verheerend effektiver, da er gleichzeitig jeden möglichen Weg in ein Netzwerk ausschöpfen kann. Für den Verteidiger ist der traditionelle „Detect and Respond“-Zyklus (Erkennen und Reagieren) mittlerweile zu langsam; wenn ein Mensch zur Validierung eines Alarms benötigt wird, ist das Netzwerk bereits kompromittiert.
Um dem entgegenzuwirken, argumentiert Mandia, dass die Verteidigung ebenso autonom werden muss wie die Offensive. Sein Unternehmen, Armaden, operiert nach der Prämisse, dass es keine tragfähige Verteidigung ohne eine Weltklasse-Offensive gibt, gegen die man trainieren kann. Durch den Einsatz von „Hyper-Angriffen“ – massiven Schwärmen von KI-Agenten, die den Metadaten-Zwilling eines Netzwerks kartieren – setzt Armaden die Kundenumgebungen unter kontinuierlichen Druck. Dies ermöglicht es ihnen, „ausnutzbare Risiken“ (exploitable risk) zu identifizieren, statt nur „Schwachstellen“ (vulnerabilities), und so zwischen einem theoretischen Bug und einem praktischen Pfad zur Remote-Code-Ausführung zu unterscheiden.
Das Gespräch hebt ein kritisches Versagen in der aktuellen KI-Sicherheit hervor: die Kluft zwischen KI-Forschern und Domain-Sicherheitsexperten. Mandia stellt fest, dass viele KI-Labore die Fähigkeiten ihrer eigenen Modelle unterschätzen, weil es ihnen an der „Red Team“-Mentalität fehlt. Armaden löst dies, indem es Exploit-Entwickler mit KI-Ingenieuren zusammenbringt und so einen „Käfig“ aus deterministischen Regeln und Klassifikatoren schafft, die es der KI ermöglichen, kreativ genug zu sein, um Zero-Day-Lücken zu finden, während gleichzeitig verhindert wird, dass sie außer Kontrolle gerät.
Mit Blick auf die Zukunft des Security Operations Center (SOC) prognostiziert Mandia einen totalen Zusammenbruch aktueller manueller Prozesse. Die „Zwiebelschalen“ der Sicherheit – Prävention, Erkennung, Reaktion – verdichten sich. Da KI sich intern mit schockierender Geschwindigkeit ausbreiten kann, besteht die einzige praktikable Strategie in einem „Kraftfeld“ aus autonomer Prävention und sofortigem, maschinengesteuertem Lockdown. Das Ziel ist der Übergang von einem „hygienebasierten“ Penetrationstesting hin zu einem Zustand kontinuierlichen, automatisierten Red-Teaming.
Schließlich reflektiert Mandia über das Unternehmertum in dieser Ära. Im Gegensatz zum selbstfinanzierten, langsam wachsenden Modell von Mandiant verlangt das KI-Zeitalter extreme Geschwindigkeit, aggressive Finanzierung und eine Go-to-Market-Strategie mit einem „Ferrari-Motor“. In einer Welt, in der sich die Technologie alle zwei Wochen ändert, ist das einzige dauerhafte Unterscheidungsmerkmal nicht das spezifische Werkzeug – welches in sechs Monaten repliziert werden kann –, sondern die Fähigkeit, die schwierigsten Probleme für die anspruchsvollsten Unternehmenskunden zu lösen und ein fanatisches Niveau an Kundenzufriedenheit aufrechtzuerhalten.
Zentrale Diskussionsthemen
Der Wechsel vom Scharfschützen zum Schwarm
Der Dialog untersucht den Übergang in der Angriffsmethodik. Traditionelle Bedrohungen auf hohem Niveau (Nationalstaaten) waren durch Tarnung und Präzision charakterisiert (die „Scharfschützenkugel“). KI führt eine „Schwarmdynamik“ ein, bei der Volumen und Geschwindigkeit die Verteidigung überwältigen. Diese Demokratisierung bedeutet, dass technisch weniger versierte Angreifer nun Ergebnisse erzielen können, die zuvor Elite-Staatsakteuren vorbehalten waren, was die Zuordnung (Attribution) erheblich erschwert.
Ausnutzbares Risiko vs. Schwachstellen-Rauschen
Ein wiederkehrender Streitpunkt ist der Unterschied zwischen traditionellem Pen-Testing und KI-gesteuerter Offensive. Mandia argumentiert, dass die meisten Sicherheitstools „Rauschen“ erzeugen, indem sie Tausende von Schwachstellen auflisten. Armaden konzentriert sich auf die Ausnutzbarkeit (exploitability) – also die tatsächliche Ausführung der Kill-Chain, um zu beweisen, dass Daten exfiltriert werden können. Dies verschiebt den Fokus des CISO von einer langen Liste an Patches hin zu einer kurzen Liste kritischer, nachgewiesener Eintrittspunkte.
Die Notwendigkeit autonomer Verteidigung
Die Sprecher sind sich einig, dass der „Mensch-im-Loop“ mittlerweile ein Risiko darstellt. In der Zeit, die ein menschlicher Analyst benötigt, um einen Alarm zu bestätigen, kann ein KI-Agent sich bereits lateral über das gesamte Netzwerk bewegt haben. Die einzige Lösung ist eine „autonome Verteidigung“, die in Millisekunden „Tourniquets“ (Abbindungen) oder kompensierende Kontrollen anwenden kann und so die „Detect and Respond“-Phase effektiv in eine „Prevent“-Phase automatisiert.
Die Konvergenz von KI-Sicherheit und Domain-Expertise
Die Diskussion geht darauf ein, warum KI-Modelle ihre Schöpfer oft „überraschen“. Mandia behauptet, dass KI-Forschern oft die investigative Erfahrung fehlt, um vorherzusehen, wie ein Modell als Waffe eingesetzt wird. Er plädiert für eine hybride Teamstruktur, in der Red-Teamer die „Evals“ (Evaluierungen) für die KI definieren, um sicherzustellen, dass das Modell gegen reale Kill-Chains und nicht gegen theoretische Sicherheitsleitplanken getestet wird.
Enterprise-Skalierung im KI-Zeitalter
Mandia kontrastiert die „Zähigkeit und Courage“ der frühen Startup-Kultur mit der heutigen Notwendigkeit „industrialisierter Prozesse“. Da der Markt nun gesättigt ist und die Technologie in rasendem Tempo voranschreitet, betont er, dass operationale Disziplin, skalierbare Führung und ein schneller Feedback-Loop zwischen Kunden und Ingenieuren die einzigen Wege sind, um „Chaos“ während des Hyper-Wachstums zu vermeiden.
Überraschende Erkenntnisse
- Die „Zero-Day“-Schwelle: KI-Agenten haben offiziell die Schwelle überschritten, von einer Unterstützung für Menschen zu einer unabhängigen Entdeckung von Zero-Day-Lücken in Produktionsumgebungen überzugehen.
- Open vs.
Here is the professional translation into German, maintaining the HTML structure and technical terminology:
“`html
Praktische Erkenntnisse
- Audit auf Ausnutzbarkeit, nicht auf Schwachstellen: Hören Sie auf, Patches allein auf Basis von CVSS-Scores zu priorisieren; priorisieren Sie stattdessen danach, ob die Schwachstelle einen nachgewiesenen Pfad zur Remote-Code-Ausführung bietet.
- Implementierung eines „Heartbeat“-Überwachungssystems: Wechseln Sie von jährlichen oder quartalsweisen Penetrationstests hin zu einem kontinuierlichen Polling-System, das eine Neubewertung auslöst, wann immer sich die Netzwerkkonfiguration oder die App-Version ändert.
- Aufbau einer „Kraftfeld“-Mentalität: Verschieben Sie das Sicherheitsbudget von der „Erkennung“ (den Bösewicht finden, nachdem er eingedrungen ist) hin zur „autonomen Prävention“ (den Eintritt innerhalb von Millisekunden stoppen).
- Hybridisierung Ihrer KI-Teams: Wenn Sie KI-Tools entwickeln, stellen Sie sicher, dass „Red Teamer“ (Exploit-Entwickler) die Evaluierungs-Frameworks entwerfen und nicht nur die KI-Forscher.
- Einführung von „Field Dressing“-Kontrollen: Implementieren Sie bei einem neuen Zero-Day-Angriff sofort „kompensierende Kontrollen“ (rudimentäre Blockaden), um die „Blutung zu stoppen“, anstatt auf einen perfekten Patch des Herstellers zu warten.
- Priorisierung von Kunden mit den „schwierigsten Problemen“: Um sich in einem überfüllten KI-Markt eine Marke aufzubauen, konzentrieren Sie sich ausschließlich auf die komplexesten Unternehmensumgebungen (Banken, Fluggesellschaften); Erfolg in diesem Segment schafft ein skalierbares „Gütesiegel“.
- Minimierung verteilter Reibungsverluste: Für High-Velocity-Engineering sollten co-lokalisierte Teams bevorzugt werden, um die Kommunikationslatenz zu verringern, die bei einer verteilten KI-Entwicklung inhärent ist.
“`
a16z General Partner David George sits down with Armadin founder and CEO Kevin Mandia to discuss what happens to cybersecurity when attackers can operate at machine speed.
After 30 years in security and building Mandiant, Kevin says AI convinced him to get back on the field. He explains how AI changes the economics of cyberattacks, allowing attackers to probe thousands of paths simultaneously, and why that means defense will ultimately need to become autonomous too.
They also unpack Armadin’s approach: continuously attacking customers’ systems with AI to find exploitable vulnerabilities before adversaries do, then building toward autonomous defenses that can respond in real time. Kevin shares what Armadin has learned from finding more than 90 zero-days in production environments this year, why humans can’t remain in the detect-and-respond loop, and how the entire security stack could change over the next few years.
Resources:
Learn more about Kevin Mandia and Armadin:https://www.armadin.com/team-members/kevin-mandia
Follow David George on X:https://x.com/DavidGeorge83
Learn more about Armadin:https://www.armadin.com/
Stay Updated:
Find a16z on YouTube: YouTube
Find a16z on X
Find a16z on LinkedIn
Listen to the a16z Show on Spotify
Listen to the a16z Show on Apple Podcasts
Follow our host: https://twitter.com/eriktorenberg
Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures.
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
-
The Future of Drone Warfare
War has always been shaped by technology—from steel and gunpowder to GPS and nuclear weapons. But the decisive technologies of tomorrow aren’t coming—they’re already here. In this episode, recorded live at our third annual American…
-
How to Build with the Department of Defense
When people think about startups working with the government, the phrase “black box” often comes up. But what if that box is finally being pried open? In this episode—recorded live at the American Dynamism Summit…
-
The Top 100 GenAI Products, Ranked and Explained
This month, a16z’s Consumer team released the fourth edition of the GenAI 100 — a data-driven ranking of the top 50 AI-first web products and mobile apps, based on unique monthly visits and active users.…
-
Jensen Huang and Arthur Mensch on Winning the Global AI Race
The global race for AI leadership is no longer just about companies—it’s about nations. AI isn’t just computing infrastructure; it’s cultural infrastructure, economic strategy, and national security all rolled into one. In this episode, Jensen…
-
Why AI Voice Feels More Human Than Ever
AI voice technology has been around for years — think Siri or Alexa — but the magic has been missing. That’s changing, and quickly! In this episode, Anish Acharya, General Partner at a16z, and Olivia…
-
From Thesis to Meme to Fund: Building American Dynamism
For over a century, the United States has been the birthplace of world-changing innovation – from the Wright brothers’ first flight to the invention of the transistor, the moon landing, and the birth of the…
-
What Founders Get Wrong About Scaling – With Carta’s CEO
Henry Ward, cofounder and CEO of Carta, has spent over a decade scaling his company from an early-stage startup to a 2,000-person industry leader. In this Speedrun conversation with a16z Games partner Josh Lu, Henry…
-
Creativity vs Control: Where AI Fits in the Creative Toolbox
Being a creator in 2025 is tough—but building for creators is even harder. Perhaps no one understands this conundrum better than Scott Belsky. As the founder of Behance, a longtime executive at Adobe, and an…
-
Who Will Own the Internet? a16z’s Chris Dixon on AI and Crypto
Technology doesn’t grow in isolation—it evolves in waves. Just as mobile, cloud, and SaaS shaped the internet of the past 20 years, so too could crypto, AI, and new hardware usher in an era of…
-
The Critical Technology in Finding Critical Materials
Critical materials like copper, lithium, and gallium have been mined for decades, but their role in core technologies, geopolitics, and the energy transition have come to a height in recent years. In this episode, a16z…
